A supply-chain attack targeting ShapedPlugin, a WordPress plugin developer with more than 400,000 active installations across its free products. The backdoored premium plugin releases were distributed through the company's official update infrastructure. The malware provided attackers with persistent access to websites, stole administrator credentials and two-factor authentication (2FA) secrets, and deployed multiple remote access mechanisms. …
The post Supply-chain attack injects backdoor on ShapedPlugin WordPress software appeared first on CyberInsider.